This website uses cookies to enhance your browsing experience. By clicking "Agree", you consent to our cookies policy.

Information security and quality policy

QUALITY POLICY

Our quality policy aims at: providing an individually tailored approach for each client; ensuring a team with the professional qualification and experience necessary for meeting each client’s requirements; providing professional services at reasonable and realistic prices.

The mission of Chronika is to be acknowledged as an organization performing high quality services by adding value to the activity of each client and as a reliable partner of foreign companies based in Bulgaria.

Chronika strictly selects and develops its experts in order to meet the highest requirements for professionalism and quality of the services provided.

The Management is committed to satisfy the requirements and to constantly improve the efficiency of the quality management system. The organization has introduced clear procedures and approaches for provision of services as well as constant update of the service portfolio thus fully meeting the market needs and requirements.

The Management is committed to review at least once a year the policy in order to ensure its full adequacy.

INFORMATION SECURITY POLICY

The main goal of “Chronika” ООD is to ensure the integrity, confidentiality and inviobility of information, both that of the company and that of clients and personal data subjects, to provide continuity of business processes and increased attention to every detail throughout the work.

This policy applies to all employees, clients, partners and other concerned parties, who have access to company information assets or are involved in the processing, storage, transfer or management of information within our organization.

“Information security” in “Chronika” ООD includes implementing a combination of technical, administrative and physical controls to protect information assets and its purpose is protect from a wide range of threats, including unauthorized access, data breaches, cyberattacks, malware, insider threats, and other vulnerabilities that may compromise the security and reliability of information and information systems.

Our information security goals are as follows:

  • To protect data confidentiality by ensuring that access is limited to authorized individuals and preventing unauthorized disclosure.
  • To protect the integrity of information by maintaining its accuracy, completeness, and reliability throughout its lifecycle.
  • To provide the accessibility of information resources and IT systems in support of business strategy and all concerned parties requirements.
  • Compliance with applicable legal, regulatory and contractual requirements related to information security.
  • Managing current and predictable information security risks and threats by implementing appropriate controls and continuously improving our adequacy of the security.
  • Promoting a culture in conformity with information security through training, awareness programs, and regular communication.

Principles of information security management at “Chronika ООD:

Confidentiality: protecting data from unauthorized access or disclosure to maintain its confidentiality.

Integrity: ensuring the accuracy, completeness and reliability of information by protecting it from unauthorized modification or deletion.

Availability: ensuring timely and reliable access to information and IT systems by authorized persons.

Risk management: identifying, assessing and mitigating information security risks to protect against potential threats and vulnerabilities.

Compliance: adherence to applicable laws, regulations, and contractual obligations related to information security.

Awareness and training: promoting a culture of information security awareness through training and education programs for all staff members.

Incident response: establishing effective incident response procedures to rapidly detect, respond to, and recover from information security incidents.

Business continuity: developing and maintaining business continuity plans to ensure the availability and timely recovery of critical information assets and IT systems.

Principle of least privilege: granting individuals only the minimum necessary access rights to fulfill their tasks and responsibilities in order to minimize the risk of unauthorized access.

Monitoring and continuous improvement: regularly reviewing and improving information security measures to adapt to evolving threats and technologies.

Project security: integrating security considerations throughout the life cycle of systems, applications, and processes – from design to implementation and maintenance.

Engagement: holding individuals accountable for their actions and ensuring compliance with information security policies and procedures.

Protection of personal data: respecting the right to privacy and inviolability of personal information in accordance with relevant laws and regulations.

Cooperation: promoting cooperation and information exchange between concerned parties to improve the overall adequacy of the security and address emerging threats.

Handling exceptions and deviations: established procedures and guidelines for handling exceptions and deviations from standard information security practices to minimize risks and maintain the overall effectiveness of the Information Security System.

Assignment of responsibilities: distribution of information security tasks, roles or functions.

We will achieve these goals and principles by maintaining and continuously improving the functioning Management System in accordance with the requirements of ISO/IEC 27001:2022.

The management of  “Chronika” ООD is responsible for the establishing and applying of the Information Security Policy and provides full support in disclosing it to concerned parties.

All heads of structural units are directly responsible and ensure that the Information Security Policy is applied by all employees of the company.

The information security policy is reviewed at least once a year during a management review.


If necessary and requested, the Information Security Policy is also provided to external considered parties in an appropriate and accepted within the company manner.

In my capacity of a Managing Partner I declare my personal participation and responsibility for the implementation

Pavlina Kalcheva

Information security and quality policy - BG Language